November 12, 2024 · Applied Cybernetics Group
CVE-2021-41277 — Metabase Metabase
Metabase GeoJSON API Local File Inclusion Vulnerability
- Added to KEV
2024-11-12- Federal due date
2024-12-03- Vendor
- Metabase
- Product
- Metabase
- EPSS
- 100.0th percentile (score 0.944, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2021-41277
CISA short description
Metabase contains a local file inclusion vulnerability in the custom map support in the API to read GeoJSON formatted data.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.